Falhas do tipo CWE-532

858 resultados

Informações sensíveis em arquivos de log

A aplicação registra dados confidenciais (senhas, tokens, PII, chaves criptográficas) em arquivos de log sem proteção adequada. Esses logs são frequentemente legíveis por outros usuários do sistema, backups desprotegidos ou ferramentas de análise, expondo segredos de negócio e credenciais de autenticação.

Exemplo

Uma API registra a requisição HTTP completa incluindo o header `Authorization: Bearer eyJhbGc...`, ou um serviço de login escreve a senha do usuário em log de debug antes de validá-la. Um atacante com acesso ao servidor (ou backups antigos) lê esses logs e obtém credenciais válidas.

Como mitigar

Nunca registre senhas, tokens, chaves, CPF ou dados de cartão. Use máscaras (ex: `token=***`) para valores sensíveis que precisam ser logados. Restrinja permissões de acesso aos arquivos de log e aplique rotação com limpeza segura de logs antigos. Implemente revisão de código e linters para detectar padrões suspeitos.

CVE-2024-42344MEDIUMA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive inEPSS 0.2%CVE-2024-45674LOWIBM Security Verify Bridge information disclosureEPSS 0.2%CVE-2025-0273MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerabilityEPSS 0.2%CVE-2025-11547HIGHAXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.EPSS 0.2%CVE-2024-41719MEDIUMBIG-IP Next Central Manager vulnerabilityEPSS 0.2%CVE-2026-40619HIGHA high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with localEPSS 0.2%CVE-2026-28261HIGHDell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an InseEPSS 0.2%CVE-2026-1622MEDIUMUnredacted data exposure in query.logEPSS 0.2%CVE-2025-36187MEDIUMMultiple Security vulnerabilities affecting IBM Knowledge Catalog Standard CartridgeEPSS 0.2%CVE-2024-42196MEDIUMHCL Launch is susceptible to Insertion of Sensitive Information into Log File vulnerabilityEPSS 0.2%CVE-2023-43043MEDIUMIBM Maximo Application Suite information disclosureEPSS 0.2%CVE-2024-7421MEDIUMAn information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to systeEPSS 0.2%CVE-2022-44745MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build EPSS 0.2%CVE-2025-43475MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access usEPSS 0.2%CVE-2026-92758MEDIUMLogs may collect sensitive informationEPSS 0.2%CVE-2025-59868MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to sensitive data exposureEPSS 0.2%CVE-2026-13750MEDIUMSnowflake CLI Sensitive Credential Exposure Through Debug LoggingEPSS 0.2%CVE-2026-18710HIGHCleartext Storage of Sensitive Information in MongoDB Driver Logging During Client InitializationEPSS 0.2%CVE-2026-45581MEDIUMfabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service ModeEPSS 0.2%CVE-2026-84525MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.EPSS 0.1%